Local Privilege Escalation in Device Policy Management by Android
CVE-2025-22442

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
2 September 2025

What is CVE-2025-22442?

A vulnerability exists in the DevicePolicyManagerService of Android, which allows the installation of unauthorized applications into a work profile due to a race condition. This flaw enables local privilege escalation without requiring additional execution privileges or user interaction. As a result, malicious actors could exploit this vulnerability to gain unauthorized access and control, raising significant security concerns for users and devices.

Affected Version(s)

Android 15

Android 14

Android 13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-22442 : Local Privilege Escalation in Device Policy Management by Android